OSG PKI transition: Experiences and lessons learned. Welch, V., Deximo, A., Hayashi, S., Khadke, V., D., Mathure, R., Quick, R., Altunay, M., Sehgal, C., S., Tiradani, A., & Basney, J. In Proceedings of Science, volume 23-28-Marc, 2014. Proceedings of Science (PoS).
OSG PKI transition: Experiences and lessons learned [link]Website  abstract   bibtex   
Over the course of 2012-13 the Open Science Grid (OSG) transitioned the identity management system for its science user community from the DOE Grids public key infrastructure (PKI) to a new OSG PKI. This transition was significant in its scope, touching on nearly all aspects of the OSG infrastructure and community. The transition also entailed the adoption of a commercial certificate service as a key component of OSG's PKI. This transition offers a rare opportunity to better understand identity management and how to prepare for and implement changes in an identity management system. In this paper, we describe OSG's transition and lessons learned from it. We discuss the overall project management approach, including a division of the project into planning, piloting, design, development, implementation and transition phases. We discuss the considered alternatives, both for implementations of the OSG PKI as well as alternatives to a PKI such as federated identity, as well as the criteria we used to make our decision. We conclude with a set of lessons learned from both implementation and in retrospect, and a set of recommendations for other identity systems. © Copyright owned by the author(s) under the terms of the Creative Commons Attribution-NonCommercial-ShareAlike Licence.
@inproceedings{
 title = {OSG PKI transition: Experiences and lessons learned},
 type = {inproceedings},
 year = {2014},
 keywords = {Authentication,Certificate Services,Distributed computer systems,Federated identity,Identit,Proj,Public key cryptography},
 volume = {23-28-Marc},
 websites = {https://www.scopus.com/inward/record.uri?eid=2-s2.0-84976287425&partnerID=40&md5=91fa0ceddc7a53735878e4a650ae9d76},
 publisher = {Proceedings of Science (PoS)},
 id = {8c76419a-92c3-3fe1-9bb0-2530167abf1d},
 created = {2019-10-01T18:06:10.964Z},
 file_attached = {false},
 profile_id = {42d295c0-0737-38d6-8b43-508cab6ea85d},
 last_modified = {2019-10-01T18:06:35.993Z},
 read = {false},
 starred = {false},
 authored = {true},
 confirmed = {true},
 hidden = {false},
 citation_key = {Welch2014},
 source_type = {conference},
 notes = {cited By 0; Conference of International Symposium on Grids and Clouds, ISGC 2014 ; Conference Date: 23 March 2014 Through 28 March 2014; Conference Code:121995},
 folder_uuids = {f285719c-254b-42e8-a6fb-527e7c80488b,ec6ad3c6-db7d-494d-863c-ef38d23f1f7e,22c3b665-9e84-4884-8172-710aa9082eaf},
 private_publication = {false},
 abstract = {Over the course of 2012-13 the Open Science Grid (OSG) transitioned the identity management system for its science user community from the DOE Grids public key infrastructure (PKI) to a new OSG PKI. This transition was significant in its scope, touching on nearly all aspects of the OSG infrastructure and community. The transition also entailed the adoption of a commercial certificate service as a key component of OSG's PKI. This transition offers a rare opportunity to better understand identity management and how to prepare for and implement changes in an identity management system. In this paper, we describe OSG's transition and lessons learned from it. We discuss the overall project management approach, including a division of the project into planning, piloting, design, development, implementation and transition phases. We discuss the considered alternatives, both for implementations of the OSG PKI as well as alternatives to a PKI such as federated identity, as well as the criteria we used to make our decision. We conclude with a set of lessons learned from both implementation and in retrospect, and a set of recommendations for other identity systems. © Copyright owned by the author(s) under the terms of the Creative Commons Attribution-NonCommercial-ShareAlike Licence.},
 bibtype = {inproceedings},
 author = {Welch, V and Deximo, A and Hayashi, S and Khadke, V D and Mathure, R and Quick, R and Altunay, M and Sehgal, C S and Tiradani, A and Basney, J},
 booktitle = {Proceedings of Science}
}

Downloads: 0